Cybersecurity Analyst – Attack Surface Management & Attack Path Analysis
Applied Materials
·2 weeks ago
- Location
- Bengaluru, KA,IN, IN
- Workplace
- Hybrid
- Type
- Full-time
- Department
- IT
- Education
- Bachelor
- Source
- Eightfold
Description
Key Responsibilities
Attack Surface Management
- Own and continuously evolve the enterprise external attack surface inventory — internet-facing assets, domains, IP ranges, cloud services, third-party integrations, and shadow IT
- Proactively discover unauthorized, unmanaged, or impersonation-related assets and investigate exposed services, SSL/TLS and DNS misconfigurations, open ports, cloud storage exposure, and leaked credentials surfaced through EASM tooling
- Track assets across the full discovery-to-remediation lifecycle and maintain authoritative records in the CAASM platform
Attack Path Analysis & Threat Exposure Modeling
- Model attack paths across hybrid on-premises, cloud, and identity infrastructure (Active Directory, Entra ID, cloud IAM) using graph-based tooling to expose lateral movement and privilege escalation opportunities
- Prioritize remediation by attack path criticality, asset business value, and exploitability — beyond CVSS — and identify choke points whose remediation eliminates the greatest number of paths
- Partner with red team, purple team, and breach-and-attack simulation engagements to validate models, mapping findings to MITRE ATT&CK and CTEM program metrics
Asset Intelligence & CAASM
- Build and maintain a unified, authoritative asset view by integrating telemetry across endpoints, cloud APIs, network scanners, CMDBs, and identity directories, enriched with criticality ratings and business ownership
- Drive asset criticality modeling and support EPM governance so the Vulnerability & Exposure Management team can prioritize remediation by business impact, not volume
Automation, Analytics & Reporting
- Build dashboards for attack surface posture, attack path risk, remediation velocity, and security KPIs for operational and executive audiences
- Develop scripting and automation (Python, REST APIs) and apply AI-assisted analytics to improve data collection, enrichment, risk correlation, and predictive risk signals
- Produce posture reports and executive summaries, and manage cybersecurity exceptions, risk acceptances, and governance documentation per policy
Cross-Functional Partnership
- Serve as the subject-matter expert on attack surface and attack path topics during architecture reviews, onboarding, and risk assessments, partnering with Vulnerability & Exposure Management, Cloud Security, Network, SOC, Application Security, and Governance teams to drive end-to-end risk reduction
- Communicate technical risk findings and remediation recommendations clearly to both technical teams and non-technical business stakeholders
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, or a related field
- 5+ years of progressive experience in Cybersecurity, Security Operations, Vulnerability/Exposure Management, or Attack Surface Management
- Hands-on experience across EASM (asset discovery and exposure analysis), CAASM (asset data integration and unified inventory), attack path / attack graph modeling across hybrid environments, and exposure-based prioritization that goes beyond basic CVSS
- Working knowledge of MITRE ATT&CK adversary techniques (initial access, lateral movement, privilege escalation, persistence)
- Hands-on experience with cloud environments (AWS, Azure, or GCP) and cloud-specific exposure risks (storage misconfigurations, IAM over-privilege, exposed APIs)
- Proficiency in scripting for automation and data analysis (Python preferred) and integrating security tools via APIs to build dashboards and workflows
- Strong written and verbal communication; able to translate technical risk into clear business language for senior stakeholders
Certifications (Preferred)
- CISSP, CISM, or CISA
- Offensive/exposure-focused: CEH, OSCP, or GIAC (GPEN, GWAPT, GCIH)
- Cloud security: AWS Security Specialty, Microsoft AZ-500, or (ISC)² CCSP
## Qualifications
### Education:
Bachelor's Degree
### Skills
### Certifications:
### Languages:
### Years of Experience:
4 - 7 Years
### Work Experience:
## Additional Information
###
### Shift:
Day (India)
###
### Travel:
Yes, 10% of the Time
###
### Relocation Eligible:
Yes
### Referral Payment Plan:
Employee Referral (Enhanced)
Applied Materials is an Equal Opportunity Employer committed to diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, national origin, citizenship, ancestry, religion, creed, sex, sexual orientation, gender identity, age, disability, veteran or military status, or any other basis prohibited by law.